A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
Social Engineering Examples·8 sources
Over the weekend of March 19-21, 2022, the LAPSUS$ extortion group (Microsoft-tracked as DEV-0537) publicly claimed to have breached Microsoft, first posting screenshots of what appeared to be internal Azure DevOps source-code repositories, then on the night of March 21 posting a torrent for a ~9GB compressed (37GB uncompressed) 7zip archive containing partial source code for over 250 internal projects, including Bing, Bing Maps, and Cortana.
On the evening of March 22, 2022, Microsoft published a blog post ("DEV-0537 criminal actor targeting organizations for data exfiltration and destruction") confirming that a single employee account had been compromised, giving the group "limited access" that was used to exfiltrate portions of source code; Microsoft stated no customer code or data was involved.
Microsoft's security team said it had already been investigating the compromised account based on threat intelligence before the actor's public disclosure, and that the disclosure let the team escalate its response and interrupt the actor "mid-operation." Microsoft did not disclose exactly how the specific employee account was compromised, but framed the intrusion as consistent with DEV-0537's broader documented playbook.
DEV-0537 is a group that, across its 2021-2022 campaign against dozens of organizations (including Okta, Nvidia, Samsung, T-Mobile, Ubisoft, Vodafone, and Globant), relied on MFA push-bombing/fatigue, SIM swapping to hijack SMS/voice MFA, buying credentials and session tokens from criminal marketplaces, and directly paying employees, suppliers, or business partners of target organizations for network credentials and MFA approval.
Two days later, on March 24, 2022, City of London Police announced the arrest of seven people aged 16-21 in connection with the LAPSUS$ investigation (one trade outlet, Computer Weekly, separately reports the arrests themselves took place March 25); researchers and the BBC identified a 16-year-old from Oxford, England (alias "White"/"Breachbase," later named as Arion Kurtaj) as an alleged ringleader who had amassed roughly $14M in Bitcoin.
Two teenagers were formally charged on April 1, 2022. In August 2023, the US Cyber Safety Review Board (CISA) published a dedicated government report on LAPSUS$ documenting the group's MFA-fatigue and SIM-swap techniques in detail and citing the Microsoft compromise as an exemplar case.
Microsoft's blog did not disclose the specific initial-access technique used against its own compromised employee account, but described it as reflecting DEV-0537/LAPSUS$'s standard TTP playbook, later corroborated in detail by CISA's Cyber Safety Review Board (CSRB) report. At a general/awareness level, the group's methods were: (1) obtaining an initial foothold via purchased credentials/session tokens from criminal forums, Redline info-stealer harvests, exposed secrets in public code repos, or by directly paying an employee/contractor/supplier for login access; (2) where SMS/voice MFA protected an account, performing a SIM swap (social-engineering or bribing telecom staff/using compromised telecom employee accounts to reassign the victim's number to an attacker-controlled SIM) to intercept one-time codes; (3) where push-based MFA was in use, "MFA fatigue"/push-bombing: repeatedly triggering approval prompts (often at inconvenient hours) until the target approved one out of annoyance, or paying/soliciting an insider to simply approve the prompt themselves; (4) in some incidents, calling the target's help desk while impersonating the employee (using previously gathered personal details/profile photos and a native-English-sounding caller) to talk support staff into resetting credentials or MFA enrollment outright.
Once inside, DEV-0537 used tools like AD Explorer to map privileged accounts, pivoted through Slack/Teams/Jira/Confluence to harvest further credentials, exploited known vulnerabilities in on-prem Jira/GitLab/Confluence servers, and exfiltrated data via NordVPN egress points geographically close to the victim to blend in. For Microsoft specifically, the actor reached an Azure DevOps source-code repository through the single compromised account.
There was no phishing email or deceptive message to the victim organization in the traditional sense. The "lure" operated on Microsoft's employee and/or the identity infrastructure protecting their account. Tell-tale signs the CSRB later flagged as detectable indicators across LAPSUS$ incidents generally: a sudden burst of MFA push notifications, especially clustered at odd hours (e.g., 1am) designed to wear the user down into approving one out of fatigue; help-desk contacts requesting password/MFA resets where the caller could not be verified through an out-of-band channel; and unexplained SIM/number-reassignment notifications from a carrier.
LAPSUS$ itself was unusually loud afterward: it publicly announced the Microsoft compromise on its own Telegram channel and torrented a 9GB (37GB uncompressed) archive of source code before Microsoft's confirmation, which is atypical for financially motivated intrusion actors and was itself the tell that first surfaced the breach publicly.
Microsoft's security team, which was already investigating the compromised account on threat-intelligence leads before LAPSUS$'s public disclosure, used that disclosure to accelerate remediation: the account was locked down/remediated and the intrusion interrupted "mid-operation." Microsoft stated no customer code or data was affected and downplayed the severity, noting it does not rely on source-code secrecy as a security control.
Separately, City of London Police announced the arrest of seven people aged 16-21 on 2022-03-24 in connection with the LAPSUS$ investigation (Computer Weekly separately reports the arrests themselves took place 2022-03-25); two teenagers (16 and 17) were charged on 2022-04-01 under the UK Computer Misuse Act and fraud statutes. The alleged ringleader, later publicly identified as Arion Kurtaj (Oxford, autistic, deemed unfit to stand trial), continued hacking while on bail (Uber, Revolut, Rockstar Games in Sept 2022); a Southwark Crown Court jury found on 2023-08-23, in a "trial of the facts" (not a conviction, given his unfitness to stand trial), that he had committed those acts, and he was sentenced 2023-12-21 to an indefinite hospital order.
A 17-year-old co-defendant was convicted (an actual conviction) for related hacks of Nvidia and BT/EE. These later findings relate to Kurtaj's broader LAPSUS$-linked spree, not specifically adjudicated as the Microsoft intrusion. In August 2023, the US CISA Cyber Safety Review Board published a dedicated review of LAPSUS$ tactics (citing the Microsoft incident) with ecosystem-wide recommendations on passwordless authentication and SIM-swap controls.
This intrusion demonstrated, at a company with world-class security engineering, that identity is the new perimeter and that MFA is not a monolithic control: SMS/voice-based MFA can be defeated wholesale via SIM swapping, and even app-based push MFA can be worn down by sheer repetition (push-bombing) or simply purchased from a bribed insider. A single compromised employee account was sufficient to reach a source-code repository, illustrating how identity compromise, not sophisticated malware or zero-days, was the common thread across LAPSUS$'s breaches of Microsoft, Okta, Nvidia, Samsung, and others.
It also showed that a threat actor's operational carelessness (LAPSUS$'s public bragging and poor OPSEC) can be what first surfaces and accelerates response to an otherwise-quiet intrusion, and that some of the most damaging intrusions against Fortune 500 identity/security ecosystems can be carried out by unsophisticated, teenage, loosely organized actors rather than nation-states, prompting the US government's first CSRB deep-dive into a purely criminal (non-nation-state) actor.
CISA's Cyber Safety Review Board (CSRB), in its July 24/Aug 10 2023 report on LAPSUS$, recommended: eliminating SMS- and voice-call-based MFA in favor of FIDO2-compliant phishing-resistant/passwordless authentication (number-matching push MFA is still vulnerable to fatigue attacks; hardware keys/passkeys are not); requiring explicit step-up authentication for sensitive actions rather than one-time login MFA; strict identity verification for help-desk password/MFA resets (out-of-band verification, callback to a pre-registered number, supervisor sign-off); telecom-side SIM-swap protections (account locks, strong ID verification, customer alerts) and FCC/FTC oversight of carriers; monitoring for anomalous MFA-prompt volume/timing (e.g., prompts at 1am) as a detection signal; segmenting/limiting source-code repository access and monitoring Azure DevOps/GitHub/GitLab for unusual access patterns; and organizational security-culture measures so employees report suspicious MFA prompts or bribery solicitations instead of acting on them.
Microsoft's own blog echoed several of these (strong MFA, no SMS/voice MFA, employee education on social engineering, help-desk verification processes).
Social Engineering Examples. “Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)”. Accessed 19 September 2026. https://socialengineeringexamples.com/microsoft-lapsus-dev-0537-intrusion-2022
DEV-0537/LAPSUS$ is documented, per Microsoft's blog and the CISA CSRB report, as researching target organizations' employees, team structures, help-desk workflows, and supply-chain relationships before initial contact, likely drawing on LinkedIn, other OSINT sources, and previously breached personal data to build convincing profiles of real staff.
Employee-facing OSINT exposure (org charts, LinkedIn, help-desk workflows) is very hard to eliminate at enterprise scale; the realistic control assumes attackers already have this profile information and hardens the identity and help-desk processes it gets used against, rather than trying to suppress the exposure itself.
The group typically obtained initial account access through multiple parallel channels: deploying commodity information-stealer malware (Redline) to harvest saved passwords and session tokens, purchasing credentials and session tokens from criminal underground marketplaces, scanning public code repositories for exposed secrets, and directly soliciting or paying employees, contractors, or suppliers, often via Telegram, for their login credentials.
Monitor for credentials exposed in breach dumps or public repos and rotate them quickly, deploy endpoint detection tuned to info-stealer malware families like Redline, and run insider-risk/anti-bribery awareness programs so employees recognize and report solicitation attempts instead of acting on them.
Where an account was protected by SMS or voice-based one-time codes, the group performed or arranged SIM-swap attacks (via telecom-employee bribery or telecom-side social engineering) to reroute the victim's phone number to an attacker-controlled device, and separately cultivated insiders willing to approve MFA prompts directly.
Eliminate SMS/voice-based MFA in favor of FIDO2-compliant hardware keys or passkeys, which are not vulnerable to SIM-swap interception, and require telecom-side protections (account locks, strong ID verification, customer alerts) so number-porting cannot be socially engineered.
With valid or purchased credentials in hand, the group logged in to internet-facing systems (VPNs, virtual desktop infrastructure, identity providers) and, where push-based MFA blocked them, repeatedly triggered approval prompts, often at inconvenient hours, until the legitimate user approved one out of fatigue or a recruited insider approved it directly.
Replace simple push-approval MFA with number-matching or phishing-resistant authentication, cap how many prompts a single login attempt can generate, and monitor for anomalous prompt volume or timing (such as a burst of requests at 1am) as an active detection signal.
The group called the target's help desk, impersonating the employee using previously gathered personal details and profile photos, with a native-English-sounding caller, to convince support staff to reset the account's password or MFA enrollment outright.
Require strict, verifiable identity checks for any help-desk password/MFA reset, such as callback to a pre-registered number, supervisor sign-off, or in-person verification, so a caller with only stolen personal details cannot talk staff into a reset.
Once inside, the group used publicly available tools such as AD Explorer to map privileged accounts and pivoted through internal collaboration platforms (Slack, Teams, Jira, Confluence) to harvest further credentials, in some cases exploiting known vulnerabilities in on-premises Jira, GitLab, or Confluence servers.
Limit standing privileged-account visibility (restrict who can run directory-enumeration tools like AD Explorer), patch known vulnerabilities in on-premises Jira/GitLab/Confluence promptly, and monitor collaboration platforms for unusual credential-harvesting activity.
The compromised credentials/session were used to reach source-code and development infrastructure, in Microsoft's case a single Azure DevOps repository holding partial source for Bing, Bing Maps, and Cortana.
Segment and tightly scope access to source-code repositories, apply least-privilege so a single compromised account cannot reach broad swaths of code, and monitor Azure DevOps/GitHub/GitLab for anomalous access patterns, consistent with the CSRB's own recommendation.
Data was moved out over consumer VPN services (NordVPN), routed through egress points geographically close to the victim to avoid triggering location-based anomaly detection.
Monitor egress traffic for connections to consumer VPN exit nodes and flag large or unusual data transfers, even when the destination IP geolocates near the victim.
Rather than deploying ransomware, the group completed its objective by publicly posting screenshots, then torrenting the stolen archive and announcing the breach on its own Telegram channel, converting the intrusion into public notoriety and extortion leverage without ever demanding a ransom payment from Microsoft specifically.
There is no technical control that prevents an attacker from choosing to publicize data it has already exfiltrated; the realistic mitigation sits upstream, at Stages 3 through 7 (phishing-resistant MFA, help-desk verification, and repository segmentation), since once the archive is out, the remaining response is limited to fast confirmation, transparency, and remediation of the kind Microsoft actually carried out.
Browse by what this case has in common with others in the library.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
Hackers bought a $10 stolen Slack session cookie, used it to reach EA's internal Slack.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Hornetsecurity documented a QR-phishing (quishing) email sent to a single employee at a US-based MSP that spoofed an MFA-reactivation notice…
A Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an…
A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a…
Between September 15 and October 13, 2021, attackers sent nearly 200 emails disguised as missed-voicemail notifications with embedded QR codes…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
A small Columbus, Ohio manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an imposter scam…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
Fraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
An interstate Indian gang used AI-generated "eye-blink" deepfake videos made from stolen social-media photos to fool Aadhaar's facial-liveness e-KYC.